CVE-2004-0171

FreeBSD <= 5.1 - Denial of Service via Out-of-Sequence TCP Packets

Title source: llm
STIX 2.1

Description

FreeBSD 5.1 and earlier, and Mac OS X before 10.3.4, allows remote attackers to cause a denial of service (resource exhaustion of memory buffers and system crash) via a large number of out-of-sequence TCP packets, which prevents the operating system from creating new connections.

References (7)

Core 7
Core References
Various Sources vendor-advisory x_refsource_apple
http://lists.seifried.org/pipermail/security/2004-May/003743.html
Various Sources vendor-advisory x_refsource_freebsd
ftp://ftp.freebsd.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-04:04.tcp.asc
Patch, Vendor Advisory third-party-advisory x_refsource_idefense
http://www.idefense.com/application/poi/display?id=78&type=vulnerabilities
Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/9792
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/4124
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/15369
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/395670

Scores

EPSS 0.0115
EPSS Percentile 78.7%

Details

Status published
Products (9)
freebsd/freebsd 4.6.2
freebsd/freebsd 4.7
freebsd/freebsd 4.8
freebsd/freebsd 4.9
freebsd/freebsd 5.0
freebsd/freebsd 5.1
freebsd/freebsd 5.2
openbsd/openbsd 3.3
openbsd/openbsd 3.4
Published Mar 15, 2004
Tracked Since Feb 18, 2026